package com.dhp.controller;

import org.springframework.security.access.annotation.Secured;
import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

import javax.annotation.security.RolesAllowed;

@RestController
@RequestMapping("/test")
public class TestController {
    @GetMapping("/test1")
    @PreAuthorize("hasAnyAuthority('update')")
    public String test1(){
        return "test1";
    }

    @GetMapping("/test2")
    @PreAuthorize("hasAnyAuthority('delete')")
    public String test2(){
        return "test2";
    }

    @GetMapping("/test3")
    public String test3(){
        return "test3";
    }
}
